Control
Large online platform doesn't detect/display content provenance
A large online platform must detect standards-compliant provenance data in distributed content, expose a UI disclosing whether content is GenAI-generated/captured, let users inspect provenance, and not strip provenance data.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
enacted, not yet applying in California (US-CA); next date 2027-01-01.
The guard to add
Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data.
In the upload or ingest handler, read embedded provenance (c2pa.Reader, c2pa-node, @contentauth/c2pa-web, or a c2patool report) and store the result with the media record: whether credentials are present, the generating system or capture device, and signature validity. Transcoding and thumbnail steps do not strip metadata (no -strip, exiftool -all=, -map_metadata -1, piexif.remove); the signed original is kept so its manifest stays inspectable. The post or media render component shows a badge stating whether provenance is available and what it says, with an inspect panel or link to the full provenance data.
Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.
What reviewers look for: a provenance read on the ingest path before content is distributed; stored provenance fields on the media record; no metadata-stripping calls in the media pipeline; a badge component and inspect panel rendered with the content that users actually see.
Example (FastAPI + c2pa-python), before:
@app.post('/upload')
async def upload(file: UploadFile):
data = await file.read()
s3.put_object(Bucket=PUBLIC_BUCKET, Key=file.filename, Body=data)After:
@app.post('/upload')
async def upload(file: UploadFile):
data = await file.read()
try:
reader = c2pa.Reader(file.content_type, io.BytesIO(data))
provenance = json.loads(reader.json())
except Exception: # no manifest or unreadable
provenance = None
key = f'media/{uuid.uuid4()}'
s3.put_object(Bucket=PUBLIC_BUCKET, Key=key, Body=data) # original bytes, manifest intact
db.media.insert(key=key, provenance=provenance, has_credentials=provenance is not None)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Upcoming dates
- : Large online platforms must detect and display content provenance (California) (California (US-CA); first application)
Every rule this guard addresses
Binding law — not yet in force or stayed (1)
- California (US-CA)
- Large online platforms must detect and display content provenance (California) Cal. Bus. & Prof. Code 22757.3.1(a) · applies from 2027-01-01